Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

82 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (10)5.3%—Siemens Simatic PCS 7Siemens Simatic Pcs7Siemens Simatic TiaportalSiemens Simatic Wincc26/11/201417/6/2026
The WinCC server in Siemens SIMATIC WinCC 7.0 through SP3, 7.2 before Update 9, and 7.3 before Update 2; SIMATIC PCS 7 7.1 through SP4, 8.0 through SP2, and 8.1; and TIA Portal 13 before Update 6 allows remote attackers to execute arbitrary code via crafted packets.
ModificadaMedia (5)2.1%—Siemens Simatic Wincc Open Architecture7/2/201417/6/2026
Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to cause a denial of service (monitoring-service outage) via malformed HTTP requests to port 4999.
ModificadaMedia (5)3.5%—Siemens Simatic Wincc Open Architecture7/2/201417/6/2026
Directory traversal vulnerability in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to read arbitrary files via crafted packets to TCP port 4999.
ModificadaAlta (7.5)5.3%—Siemens Simatic Wincc Open Architecture7/2/201417/6/2026
The integrated web server in Siemens SIMATIC WinCC OA before 3.12 P002 January allows remote attackers to execute arbitrary code via crafted packets to TCP port 4999.
ModificadaMedia (5)1.7%—Siemens Simatic Wincc Open Architecture7/2/201417/6/2026
Siemens SIMATIC WinCC OA before 3.12 P002 January uses a weak hash algorithm for passwords, which makes it easier for remote attackers to obtain access via a brute-force attack.
ModificadaAlta (9.3)7.1%—Siemens Simatic Wincc Flexible RuntimeSiemens Simatic Wincc Runtime16/9/201116/6/2026
Heap-based buffer overflow in the Siemens WinCC Runtime Advanced Loader, as used in SIMATIC WinCC flexible Runtime and SIMATIC WinCC (TIA Portal) Runtime Advanced, allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted packet to TCP port 2308.
ModificadaAlta (7.8)0.55%—Siemens Simatic WinccSiemens Simatic PCS 722/7/201016/6/2026
Siemens Simatic WinCC and PCS 7 SCADA system uses a hard-coded password, which allows local users to access a back-end database and gain privileges, as demonstrated in the wild in July 2010 by the Stuxnet worm, a different vulnerability than CVE-2010-2568.
Orbitaley — Vulnerabilidades